{"slug": "hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026", "title": "HD Moore Finds 86,000 Server Backdoor Chips Exposed at Black Hat 2026", "summary": "HD Moore, founder and CEO of runZero, will present at Black Hat USA 2026 on August 5, revealing that 86,000 server backdoor chips are exposed, based on his research into baseboard management controllers (BMCs) and IPMI vulnerabilities. The talk, 'Lights Out: BMCs Are Still Broken and Now We Have the Receipts,' highlights ongoing risks from CVE-2013-4786 and new findings, including 36,872 hosts exposing IPMI on UDP port 623 and 24,650 responding to RAKP pre-authentication, as well as a new high-severity Supermicro BMC firmware issue (CVE-2026-3821). Moore will also release OOBscan, an open-source auditing tool.", "body_md": "*A server management layer most people never see is back in the spotlight because HD Moore is taking BMC security to Black Hat, and the old IPMI problem still deserves attention.*\n\nHD Moore's Black Hat USA 2026 session is not about a flashy new exploit against an AI model. It is about the small management controller sitting underneath the servers that run everything else. That is the danger. At Black Hat's Las Vegas briefings on August 5, Moore, the founder and CEO of runZero, is scheduled to present *Lights Out: BMCs Are Still Broken and Now We Have the Receipts*, a 40-minute talk on baseboard management controllers, or BMCs, and the exposed management interfaces companies still leave within reach.\n\nYou probably don't think about BMCs when you think about cloud computing. Your provider does. A BMC is a separate computer on the server motherboard, built so administrators can reboot a crashed machine, install an operating system, check hardware health, or reach a box when the main operating system is down. Supermicro describes the BMC as the part that lets administrators monitor and manage server events remotely through IPMI. That access is useful. It is also powerful enough to be dangerous when the management plane is exposed or left running old firmware.\n\nThe old wound here is CVE-2013-4786, and it is not subtle. The National Vulnerability Database says IPMI 2.0's RAKP authentication can let a remote attacker obtain password hashes from a BMC and then run offline password guessing attacks. No need to keep hammering the login screen. No normal lockout pressure. You get the hash and work on it elsewhere. Rapid7's 2013 write-up, published when Moore was still best known to many readers for Metasploit, put the issue plainly: the IPMI 2.0 process sends a salted hash before the client has authenticated.\n\nThat was 13 years ago.\n\n## The fresh problem is exposure\n\nBlack Hat's own schedule confirms Moore's session for Wednesday, August 5, in the Network Security and Hardware / Embedded tracks, and runZero's July event post says he is also releasing OOBscan, an open-source tool for auditing IPMI-exposed devices. That is the practical part. If you run servers, the question is not whether BMCs exist somewhere in your stack. They do. The question is whether you know where they are, what firmware they run, and whether anyone outside the management network can touch them.\n\nSupermicro's July 2026 advisory shows why this is not just a museum piece from 2013. The company listed CVE-2026-3821 as a high-severity issue in Supermicro BMC firmware affecting select motherboard SKUs, with updated BMC firmware required for mitigation. Supermicro says it is not aware of malicious use in the wild. Keep that sentence. It matters. The absence of known exploitation does not make an exposed management controller harmless, but it does keep the story anchored in what has actually been reported.\n\nThere is also current scanning work beyond Moore's talk. Lava's research, published in late July, said it found 36,872 unique hosts exposing IPMI on UDP port 623 on May 6, 2026, and 24,650 of tested endpoints returned at least one RAKP response before client authentication. Those are not abstract numbers. They are the shape of a very old security problem still visible on the public internet.\n\n## AI servers do not get a pass\n\nYou should care even if your company never bought a rack directly from Supermicro, Dell, Lenovo, HPE, or any of the other server names in this market. The AI buildout runs on ordinary data center plumbing. GPUs get the headlines, but every machine still has a motherboard, firmware, remote management, and a low-level control path that does not care how expensive the accelerator card is.\n\nThat is where the AI boom makes this story sharper. Companies are spending heavily on compute, booking GPU capacity months out, and treating server availability as a competitive weapon. Fine. But if the management controller under that capacity is reachable from the wrong network, the shiny part of the rack is not the only thing that matters. A weak BMC setup can turn a server into someone else's machine before the operating system has a chance to defend itself.\n\nThe fix is dull. That is the point. Keep BMC management interfaces off the public internet. Put them on isolated management networks. Disable IPMI over LAN when you don't need it. Use strong, unique passwords, and patch BMC firmware with the same seriousness you bring to operating systems and hypervisors. HPE's own guidance on the IPMI RAKP issue recommends leaving IPMI over LAN disabled when customers are not actively using it.\n\nFrankly, this is the kind of risk companies love to postpone because it sits below the application layer and outside the product roadmap. Don't. A server you cannot really manage securely is not secure just because the workload on top of it is modern.\n\n**Also read:** [China's Z.ai Says Its New Model Nears Anthropic's Mythos 5 on Cyber Tests](https://startupfortune.com/chinas-zai-says-its-new-model-nears-anthropics-mythos-5-on-cyber-tests/) • [Guangdong Taps Alibaba to Power Its AI and Semiconductor Push](https://startupfortune.com/guangdong-taps-alibaba-to-power-its-ai-and-semiconductor-push/) • [Marlow Wants to End the Tradeoff Between AI Speed and Code Ownership](https://startupfortune.com/marlow-wants-to-end-the-tradeoff-between-ai-speed-and-code-ownership/)", "url": "https://wpnews.pro/news/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026", "canonical_source": "https://startupfortune.com/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026/", "published_at": "2026-08-14 11:34:26+00:00", "updated_at": "2026-08-14 11:47:01.968569+00:00", "lang": "en", "topics": ["ai-infrastructure", "ai-safety", "ai-policy"], "entities": ["HD Moore", "runZero", "Black Hat USA 2026", "Supermicro", "CVE-2013-4786", "CVE-2026-3821", "OOBscan", "Lava"], "alternates": {"html": "https://wpnews.pro/news/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026", "markdown": "https://wpnews.pro/news/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026.md", "text": "https://wpnews.pro/news/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026.txt", "jsonld": "https://wpnews.pro/news/hd-moore-finds-86000-server-backdoor-chips-exposed-at-black-hat-2026.jsonld"}}